Back to skill

Security audit

Clash Controller

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it claims, but it embeds a Clash controller secret and can change local proxy routing from broad commands without a clear confirmation step.

Review carefully before installing. Use it only with a local Clash controller you control, rotate or replace the bundled API secret, avoid configuring Clash with a publicly shipped secret, and require explicit Clash-specific commands or confirmation before allowing it to change proxy routing.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
skill.js:3
Finding

Hardcoded Clash API Bearer Secret

Content
View full analysis

Vulnerability Details

File Location: skill.js, lines 3 and 13
Vulnerability Type: Hardcoded authentication credential
Risk Level: Medium

Vulnerable Code

js
const secret = 'ff62c2da-1504-446b-986f-f13ba034e8a5';

The credential is subsequently placed in the authorization header:

js
headers: {
  'Authorization': `Bearer ${secret}`,
  'Content-Type': 'application/json'
}

Technical Analysis

The bearer secret protecting the Clash External Controller API is embedded directly in distributable source code. Anyone who can read the skill package, a copied archive, or source-control history can recover the credential without authentication.

The code sends requests exclusively to 127.0.0.1:61222, which limits exposure to entities able to reach the host-local controller. However, hardcoding still defeats credential confidentiality and enables an untrusted local user or process to authenticate to any controller instance configured with this secret. Exposure may become broader if port forwarding, container networking, or another local relay makes the controller reachable.

Attack Path

  1. An attacker obtains read access to the skill package or its source history.
  2. The attacker extracts the bearer secret from skill.js.
  3. From a context capable of reaching the Clash controller on port 61222, the attacker submits requests with Authorization: Bearer <extracted-secret>.
  4. The controller accepts the attacker as an authenticated API client.
  5. The attacker invokes available Clash API operations to inspect or alter proxy configuration and routing.

Impact Assessment

Successful exploitation grants the access provided by the Clash External Controller API under the exposed credential. This can include reading proxy state and changing traffic-routing selections, such as switching between proxy groups and direct routing. The demonstrated skill operations modify GLOBAL ...[truncated 279 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the bearer secret from skill.js and all distributable artifacts.
  2. Rotate the exposed Clash controller secret because it must be treated as compromised.
  3. Load the credential at runtime from a protected environment variable, operating-system credential store, or user-owned configuration file.
  4. Fail closed when the credential is missing rather than using a bundled default.
  5. Restrict any credential file to the account running the skill and prevent it from being committed to source control.
  6. Continue binding the controller to 127.0.0.1 and avoid exposing or forwarding its port to untrusted networks.
  7. Add secret-scanning checks to development and release workflows to prevent recurrence.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes broad phrases like '代理', '开启代理', and '状态', which can easily overlap with ordinary user requests and cause the skill to activate unintentionally. Because this skill performs system-level proxy/process control, accidental invocation could change network routing or disable connectivity without the user explicitly intending to use this specific skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The natural-language description, trigger phrases, headings, and sample dialogue are all written to operate in Chinese, while no opt-in, locale choice, or region-specific justification is provided. This can violate a language/locale policy that requires offering users a choice rather than implicitly forcing one language.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The status-view triggers include especially ambiguous phrases such as '查看代理' and '状态', which are common in normal conversation and not uniquely tied to Clash. In context, ambiguity is more dangerous because this skill is not read-only overall: an agent misrouting intent to this skill may expose local proxy status or chain into operational commands in a sensitive networking context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill performs state-changing requests to the local Clash controller API immediately based on loose keyword matching, without any confirmation, authorization check, or safety prompt. In an agent setting, ambiguous input such as commands containing '开', '关', or proxy-related phrases can unintentionally toggle network routing, affecting privacy, connectivity, and downstream security controls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill includes hardcoded Chinese trigger terms and primarily Chinese output strings, but provides no indication that the language choice is optional or user-configurable. This can violate a language/locale policy when a skill imposes a specific language without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.